Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think this description is accurate. It makes no sense for an invisible iframe to display the entire ebay homepage to the user - people would notice 100's of server connections and an extra 1MB download for a page view. More likely they found the one Javascript file on ebay that creates the cookie, and ONLY loads that Javascript.


Well, I know that's how _lots_ of people did it in 2003/2004. The guys I hang out with (ahem...) were some of them. In the more shady parts of the internet it's actually still quite common today. Nobody notices anything.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: